Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,337 advisories

Loading
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the... Moderate Unreviewed
CVE-2026-102879 was published Sep 29, 2026
euriconicacio Credited to euriconicacio
cruzryan Credited to cruzryan
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization Moderate
CVE-2026-77310 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
thientd Credited to thientd and pussycat0x pussycat0x pussycat0x
A vulnerability was detected in October CMS up to 4.3.4. This affects the function... Moderate Unreviewed
CVE-2026-101005 was published Sep 28, 2026
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this... Moderate Unreviewed
CVE-2026-100901 was published Sep 28, 2026
ProTip! Advisories are also available from the GraphQL API